CVE-2025-8731 - CVE House
Back to Database
Status published Critical CVE-2025-8731

TRENDnet TI-G160i/TI-PG102i/TPL-430AP SSH Service default credentials

Vulnerability Description

A vulnerability was identified in TRENDnet TI-G160i, TI-PG102i and TPL-430AP up to 20250724. This affects an unknown part of the component SSH Service. The manipulation leads to use of default credentials. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The vendor explains: "For product TI-PG102i and TI-G160i, by default, the product's remote management options are all disabled. The root account is for troubleshooting purpose and the password is encrypted. However, we will remove the root account from the next firmware release. For product TPL-430AP, the initial setup process requires user to set the password for the management GUI. Once that was done, the default password will be invalid."

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-8731

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • nich0las (VulDB User)

Affected Vendor

Affected Software

TI-G160i, TI-PG102i, TPL-430AP
Vulnerable Versions:
20250724

Timeline

Official Publish: August 8th, 2025
Last Modified: August 13th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.